Skip to content

Clop Extortion: Philips and General Electric Investigate Data Theft via PTC Vulnerability

Bottom line: The ransomware group Clop has compromised at least 43 organizations, including Philips, General Electric and Shell, via a vulnerability in PTC Windchill and FlexPLM that has been patched since June.

Following Shell, two more major corporations, Philips and General Electric, are reporting possible compromises by the ransomware group Clop. The basis is a critical vulnerability in the product lifecycle software PTC Windchill and PTC FlexPLM, which is used across industries including aerospace, automotive, and medical technology.

A Philips spokesperson confirmed to Reuters an attempted compromise of a single company server used for internal data, which was successfully contained. Customer environments were reportedly not affected. General Electric was more reticent in comments to BleepingComputer, confirming only that it was aware of the claim and currently investigating it. Already on Friday, Shell had acknowledged a possible security incident after Clop claimed the theft of 89 gigabytes of data. All three companies appear on Clop’s leak site within a group of 43 new alleged victims in total.

According to current findings, the attackers exploited a critical vulnerability in internet-facing installations of PTC Windchill and PTC FlexPLM. According to PTC, more than 30,000 customers worldwide use the affected products, with more than 1,500 brand and retail customers registered for FlexPLM alone. Clop claims to have stolen backup copies, project plans, facility photos, as well as technical drawings and design plans belonging to the affected companies. For CISOs with PTC installations in their supply chain or product development process, this represents a concrete risk to intellectual property and design data, regardless of whether their own company is directly affected.

PTC released security updates for the underlying vulnerability as early as June 17 and informed customers in a private notice about possible indicators of compromise, without confirming active exploitation at that time. In the meantime, both the security firm ReliaQuest and the Ransomware Information Sharing and Analysis Centre have confirmed the attacks carried out by Clop on Windchill and FlexPLM, in which data was exfiltrated via injected web shells. The US cybersecurity agency CISA added the vulnerability to its catalog of known exploited vulnerabilities after a warning from PTC about increased attack activity, and required US federal agencies to secure their systems within three days. Germany’s BSI also stated that it warned PTC customers about the vulnerability overnight and urged them to install updates as quickly as possible.

Clop has been known for years for attacks on widely used enterprise software, including campaigns against Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, which is estimated to have affected more than 2,770 organizations worldwide. Since early August 2025, the group has also been exploiting a vulnerability in Oracle E-Business Suite and has stolen sensitive files from organizations such as the Washington Post, Harvard University, University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and Envoy Air. The US State Department is now offering a reward of 10 million US dollars for information linking Clop to a foreign government. CISOs with PTC Windchill or FlexPLM installations should immediately check the patch status of their systems and search for indicators of compromise, particularly injected web shells.


Source: www.it-daily.net · Published August 18, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: